LastPass password vaults crackable for $100, alleges 1Password
appleinsider.com
appleinsider.com
Headline reads as someone is offering as a service. Anyone else read it like that?
Shrewd business decision of course, but spammy and annoying to hear from a spokesperson's mouth.
For example, if the master password is one of the 100k most common passwords, can the attacker loop through those passwords and attempt to open the vault with each? So there would only be 100k iterations required? Or does each check need its own set of iterations?
This is exactly what a password-key derivation function is. Each check is an independent process involving the unique salt stored in cleartext. Normally (OWASP recommendations) each password check is about 310,000 iterations of SHA256, or a more complex construction like Argon2.
The problem here is that LastPass had 5000 iterations of SHA256 for a lot of accounts, and some accounts mysteriously have even lower iteration counts.
"Never attribute to malice that which is adequately explained by stupidity."
(There are some existing ideas, but they often rely on the domain/url staying the same and that's often not the case in practice)
It's not for everyone, but it's trivial to conceptualize ALL of it - you decrypt/encrypt plain text files in a dir, and something else syncs them. Your "manager" then becomes a tool with a nice CLI that just does `gpg -e`/`gpg -d` under the covers.
(I'd really like to see a tool that can take a publicly-shareable config file (email, name, country, origin date, keysize, seed) + a secret BIP39 phrase and spit out a GPG secret key, or better, just provision a new Yubikey from the phrase. Then my cold storage could just be my BIP39 phrase, rather than being my BIP39 phrase and an encrypted copy of my GPG key backup.)
I use gopass with keys stored on yubikeys, which I think is secure enough. For syncing I use git, but since decoding the synced archive requires a key that is impossible to extract from my hardware keys I'm not that worried about leaks from the syncing.
It can - but needn't - be sync'd any number of ways (iCloud, Dropbox, Google Drive, OneDrive, WebDAV), if that's what you like. Because it has WebDAV sync support, you can use it with ownCloud or NextCloud without much fuss, and not have to trust a third party at all.
But what I love best is their payment plans: the have the rare option for lifetime plans.
Something to note is that the regular "random" standard library module in python is not intended for password generation or cryptographic purposes. Modern python has a module called "secrets" that provides secure random functions using randomness from the OS's CSPRNG.
If I need something like a binary key I just use /dev/urandom directly. You can pipe urandom through something like "tr" to remove non-printable bytes, or remove everything that's not in a set that you provide such as "a-zA-Z0-9!@#$%^&*()".
On Android I use the "pass" app, but I generate the passwords on my desktop and then share them with the phone after encrypting them with the phone's GPG key.
(wordlists) https://www.eff.org/dice
The difference between being breached and not being breached is huge and this authors mindset about 1passwords security would change a lot if he was in Lastpass shoes.
We experienced a lack of understanding on the user side that this secret key needs to be printed and stored safely. It feels like a huge barrier for the adoption of 1Password for non-IT affine people.
This and other challenges led us to develop heylogin which does not require a master password and has no secret key that needs to be printed. Instead we generate cryptographic keys using the user's smartphone. For providing your desktop browser temporary access to passwords you simply confirm on your smartphone. This feels similar to modern SSO solutions but is technically a password manager.
It's only if you're adding another device or logging in online, or replacing a lost first device with no backup, that you need the 2nd piece of key material.